Esc
Proc Filesystem - T1003.007
(ATT&CK® Technique)
Definition
Adversaries may gather credentials from the proc filesystem or /proc. The proc filesystem is a pseudo-filesystem used as an interface to kernel data structures for Linux based systems managing virtual memory. For each process, the /proc/<PID>/maps file shows how memory is mapped within the process’s virtual address space. And /proc/<PID>/mem, exposed for debugging purposes, provides access to the process’s virtual address space.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.